Lucene search

K
owncloudOwnCloudOWNCLOUD:CVE-2021-35949
HistoryAug 02, 2021 - 12:00 a.m.

Shareinfo url doesn't verify file drop permissions - ownCloud

2021-08-0200:00:00
owncloud.com
12
owncloud
permission check
file drop
shareinfo api
upload only
software

EPSS

0.001

Percentile

36.2%

The permission check for a file drop (upload only share) could be circumvented by using the shareinfo API. This allowed to see from the files in the filedrop but didn’t allow downloads.

Affected configurations

Vulners
Node
owncloudcoreRange<10.8.0
VendorProductVersionCPE
owncloudcore*cpe:2.3:a:owncloud:core:*:*:*:*:*:*:*:*

EPSS

0.001

Percentile

36.2%